PluginProbe
Jetpack – WP Security, Backup, Speed, & Growth / 16.3-a.1
Jetpack – WP Security, Backup, Speed, & Growth v16.3-a.1
16.3-a.3 16.3-a.1 16.2 16.2-beta 12.0.3 12.1.3 12.2.3 12.3.2 12.4.2 12.5.2 12.6.4 12.7.3 12.8.3 12.9.5 13.0.2 13.1.5 13.2.4 13.3.3 13.4.5 13.5.2 13.6.2 13.7.2 13.8.3 13.9.2 14.0.1 All 504 releases
← All changes | json-endpoints/class.wpcom-json-api-update-post-endpoint.php +31 -23 12.0.3 → 16.3-a.1 View file →
@@ -8,8 +8,12 @@
8 8 * Delete a post: /sites/%s/posts/%d/delete
9 9 * Restore a post: /sites/%s/posts/%d/restore
10 10 */
11 11
12 +if ( ! defined( 'ABSPATH' ) ) {
13 + exit( 0 );
14 +}
15 +
12 16 new WPCOM_JSON_API_Update_Post_Endpoint(
13 17 array(
14 18 'description' => 'Create a post.',
15 19 'group' => 'posts',
@@ -196,8 +200,10 @@
196 200 );
197 201
198 202 /**
199 203 * Update post endpoint class.
204 + *
205 + * @phan-constructor-used-for-side-effects
200 206 */
201 207 class WPCOM_JSON_API_Update_Post_Endpoint extends WPCOM_JSON_API_Post_Endpoint {
202 208 /**
203 209 * WPCOM_JSON_API_Update_Post_Endpoint constructor.
@@ -250,14 +256,15 @@
250 256 * @param int $blog_id Blog ID.
251 257 * @param int $post_id Post ID.
252 258 */
253 259 public function write_post( $path, $blog_id, $post_id ) {
254 - $new = $this->api->ends_with( $path, '/new' );
255 - $args = $this->query_args();
260 + $delete_featured_image = null;
261 + $new = $this->api->ends_with( $path, '/new' );
262 + $args = $this->query_args();
256 263
257 264 // unhook publicize, it's hooked again later -- without this, skipping services is impossible.
258 265 if ( defined( 'IS_WPCOM' ) && IS_WPCOM ) {
259 - remove_action( 'save_post', array( $GLOBALS['publicize_ui']->publicize, 'async_publicize_post' ), 100, 2 );
266 + remove_action( 'save_post', array( $GLOBALS['publicize_ui']->publicize, 'async_publicize_post' ), 100 );
260 267 add_action( 'rest_api_inserted_post', array( $GLOBALS['publicize_ui']->publicize, 'async_publicize_post' ) );
261 268 }
262 269
263 270 if ( $new ) {
@@ -336,9 +343,9 @@
336 343 if ( ( isset( $input['status'] ) && 'publish' === $input['status'] ) && 'publish' !== $post->post_status && ! current_user_can( 'publish_post', $post->ID ) ) {
337 344 $input['status'] = 'pending';
338 345 }
339 346 $last_status = $post->post_status;
340 - $new_status = isset( $input['status'] ) ? $input['status'] : $last_status;
347 + $new_status = $input['status'] ?? $last_status;
341 348
342 349 // Make sure that drafts get the current date when transitioning to publish if not supplied in the post.
343 350 $date_in_past = ( strtotime( $post->post_date_gmt ) < time() );
344 351 if ( 'publish' === $new_status && 'draft' === $last_status && ! isset( $input['date_gmt'] ) && $date_in_past ) {
@@ -474,12 +481,12 @@
474 481 $insert['menu_order'] = $input['menu_order'];
475 482 unset( $input['menu_order'] );
476 483 }
477 484
478 - $publicize = isset( $input['publicize'] ) ? $input['publicize'] : null;
485 + $publicize = $input['publicize'] ?? null;
479 486 unset( $input['publicize'] );
480 487
481 - $publicize_custom_message = isset( $input['publicize_message'] ) ? $input['publicize_message'] : null;
488 + $publicize_custom_message = $input['publicize_message'] ?? null;
482 489 unset( $input['publicize_message'] );
483 490
484 491 if ( isset( $input['featured_image'] ) ) {
485 492 $featured_image = trim( $input['featured_image'] );
@@ -486,18 +493,18 @@
486 493 $delete_featured_image = empty( $featured_image );
487 494 unset( $input['featured_image'] );
488 495 }
489 496
490 - $metadata = isset( $input['metadata'] ) ? $input['metadata'] : null;
497 + $metadata = $input['metadata'] ?? null;
491 498 unset( $input['metadata'] );
492 499
493 - $likes = isset( $input['likes_enabled'] ) ? $input['likes_enabled'] : null;
500 + $likes = $input['likes_enabled'] ?? null;
494 501 unset( $input['likes_enabled'] );
495 502
496 - $sharing = isset( $input['sharing_enabled'] ) ? $input['sharing_enabled'] : null;
503 + $sharing = $input['sharing_enabled'] ?? null;
497 504 unset( $input['sharing_enabled'] );
498 505
499 - $sticky = isset( $input['sticky'] ) ? $input['sticky'] : null;
506 + $sticky = $input['sticky'] ?? null;
500 507 unset( $input['sticky'] );
501 508
502 509 foreach ( $input as $key => $value ) {
503 510 $insert[ "post_$key" ] = $value;
@@ -535,8 +542,9 @@
535 542 }
536 543
537 544 $post_id = wp_insert_post( add_magic_quotes( $insert ), true );
538 545 } else {
546 + // @phan-suppress-next-line PhanPossiblyUndeclaredVariable -- $post is set and validated several blocks earlier if $new (only set once) is falsy.
539 547 $insert['ID'] = $post->ID;
540 548
541 549 // wp_update_post ignores date unless edit_date is set
542 550 // See: https://codex.wordpress.org/Function_Reference/wp_update_post#Scheduling_posts
@@ -616,9 +624,9 @@
616 624
617 625 // Set sharing status of the post.
618 626 if ( $new ) {
619 627 $sharing_enabled = isset( $sharing ) ? (bool) $sharing : true;
620 - if ( false === $sharing_enabled ) {
628 + if ( ! $sharing_enabled ) {
621 629 update_post_meta( $post_id, 'sharing_disabled', 1 );
622 630 }
623 631 } elseif ( isset( $sharing ) && true === $sharing ) {
624 632 delete_post_meta( $post_id, 'sharing_disabled' );
@@ -668,9 +676,9 @@
668 676 foreach ( $service_connections as $service_connection ) {
669 677 update_post_meta( $post_id, $GLOBALS['publicize_ui']->publicize->POST_SKIP . $service_connection->unique_id, 1 );
670 678 }
671 679 }
672 - } elseif ( is_array( $publicize ) && ( count( $publicize ) > 0 ) ) {
680 + } elseif ( is_array( $publicize ) && ( $publicize !== array() ) ) {
673 681 foreach ( $GLOBALS['publicize_ui']->publicize->get_services( 'all' ) as $name => $service ) {
674 682 /*
675 683 * We support both indexed and associative arrays:
676 684 * * indexed are to pass entire services
@@ -677,14 +685,14 @@
677 685 * * associative are to pass specific connections per service
678 686 *
679 687 * We do support mixed arrays: mixed integer and string keys (see 3rd example below).
680 688 *
681 - * EG: array( 'twitter', 'facebook') will only publicize to those, ignoring the other available services
682 - * Form data: publicize[]=twitter&publicize[]=facebook
683 - * EG: array( 'twitter' => '(int) $pub_conn_id_0, (int) $pub_conn_id_3', 'facebook' => (int) $pub_conn_id_7 ) will publicize to two Twitter accounts, and one Facebook connection, of potentially many.
684 - * Form data: publicize[twitter]=$pub_conn_id_0,$pub_conn_id_3&publicize[facebook]=$pub_conn_id_7
685 - * EG: array( 'twitter', 'facebook' => '(int) $pub_conn_id_0, (int) $pub_conn_id_3' ) will publicize to all available Twitter accounts, but only 2 of potentially many Facebook connections
686 - * Form data: publicize[]=twitter&publicize[facebook]=$pub_conn_id_0,$pub_conn_id_3
689 + * EG: array( 'linkedin', 'facebook') will only publicize to those, ignoring the other available services
690 + * Form data: publicize[]=linkedin&publicize[]=facebook
691 + * EG: array( 'linkedin' => '(int) $pub_conn_id_0, (int) $pub_conn_id_3', 'facebook' => (int) $pub_conn_id_7 ) will publicize to two LinkedIn accounts, and one Facebook connection, of potentially many.
692 + * Form data: publicize[linkedin]=$pub_conn_id_0,$pub_conn_id_3&publicize[facebook]=$pub_conn_id_7
693 + * EG: array( 'linkedin', 'facebook' => '(int) $pub_conn_id_0, (int) $pub_conn_id_3' ) will publicize to all available LinkedIn accounts, but only 2 of potentially many Facebook connections
694 + * Form data: publicize[]=linkedin&publicize[facebook]=$pub_conn_id_0,$pub_conn_id_3
687 695 */
688 696
689 697 // Delete any stale SKIP value for the service by name. We'll add it back by ID.
690 698 delete_post_meta( $post_id, $GLOBALS['publicize_ui']->publicize->POST_SKIP . $name );
@@ -748,9 +756,9 @@
748 756
749 757 $meta = (object) $meta;
750 758
751 759 if (
752 - in_array( $meta->key, Jetpack_SEO_Posts::POST_META_KEYS_ARRAY, true ) &&
760 + in_array( $meta->key ?? null, Jetpack_SEO_Posts::POST_META_KEYS_ARRAY, true ) &&
753 761 ! Jetpack_SEO_Utils::is_enabled_jetpack_seo()
754 762 ) {
755 763 return new WP_Error( 'unauthorized', __( 'SEO tools are not enabled for this site.', 'jetpack' ), 403 );
756 764 }
@@ -778,12 +786,12 @@
778 786 continue;
779 787 }
780 788 }
781 789
782 - $unslashed_meta_key = wp_unslash( $meta->key ); // should match what the final key will be.
783 - $meta->key = wp_slash( $meta->key );
784 - $unslashed_existing_meta_key = wp_unslash( $existing_meta_item->meta_key );
785 - $existing_meta_item->meta_key = wp_slash( $existing_meta_item->meta_key );
790 + $unslashed_meta_key = isset( $meta->key ) ? wp_unslash( $meta->key ) : null; // should match what the final key will be.
791 + $meta->key = isset( $meta->key ) ? wp_slash( $meta->key ) : null;
792 + $unslashed_existing_meta_key = isset( $existing_meta_item->meta_key ) ? wp_unslash( $existing_meta_item->meta_key ) : null;
793 + $existing_meta_item->meta_key = isset( $existing_meta_item->meta_key ) ? wp_slash( $existing_meta_item->meta_key ) : null;
786 794
787 795 // make sure that the meta id passed matches the existing meta key.
788 796 if ( ! empty( $meta->id ) && ! empty( $meta->key ) ) {
789 797 $meta_by_id = get_metadata_by_mid( 'post', $meta->id );